Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Cybersecurity Policy Analyst (SSA) image - Rise Careers
Job details

Cybersecurity Policy Analyst (SSA)

Founded in 2003, IT Concepts’ core values – customer-centricity, teamwork, drive to deliver, innovation, and integrity – ensure we work together to be the best, realize objectives, and positively impact our communities. We intentionally created and sustain our ITC culture that embraces change, experimentation, continuous learning, and improvement. We bring our design thinking problem-solving approach that challenges assumptions, prioritizes curiosity, and invites complexity to deliver innovative, efficient, and effective solutions. As we continue to grow in the support of our government customers, we are looking for driven and innovative individuals to join our team.


IT Concepts, INC. (ITC) seeks a Cybersecurity Policy Analyst to become a vital part of our team and offer invaluable support to the Social Security Administration’s Office of Information Security (OIS) in building and maintaining robust policy frameworks and procedures. We are looking for a candidate who possesses a profound grasp of the NIST Cybersecurity Framework (CSF) version 2.0 and has experience reviewing policies for government agencies based on CSF. Additionally, a solid understanding of the NIST Risk Management Framework is crucial.

Responsibilities:

  • Supporting the OIS Policy Team in developing, maintaining, automating, and storing policy products and program roadmap(s).
  • Research and analyze updated language for the ISP, POMS, AIMS, and CUI in accordance with NIST, OMB, FISMA, other federal mandates, and unknown emerging sources and ensure all controls are wholly and accurately incorporated into policy.
  • Conduct reviews of documents published in the policy ecosystem to ensure accuracy and validity related to changes, updates, enhancements, and new products related to NIST 800-53. Reviews will be used to confirm ownership, add relevant documents, archive retired documents, and replace archived documents with updated ones.
  • Conduct annual reviews and updates of POMS and CUI to address gaps and discrepancies.
  • Enhancing ecosystem authoring, change, approval, and publishing workflow processes to improve efficiencies and automate where possible.
  • Assisting in developing new policies to address identified gaps in the existing framework.
  • Prepare policy and supplemental document updates for publication, track changes, and capture metrics concerning published changes.
  • Support policy waiver lifecycle by participating in meetings, recording notes, and action items.
  • Facilitate and participate in policy and risk-related discussions, assisting with meeting logistics and recording action items.
  • Recommend and implement communication techniques to effectively promote the ecosystem and policy changes to our end users.
  • Research and respond to requests for audit artifacts and findings related to the security policy or other ecosystem documents.
  • Develop weekly reports across the various tasks.
  • Continue to enhance the ecosystem user interface for ease of customer use.

Location: Hybrid in Woodlawn, MD

Pay Range: $65-85/hour. Factors affecting pay within this range may include geography/market, skills, education, experience, and other qualifications of the successful candidate.

  • Bachelor's degree in computer science, information technology, or a related field.
  • 1-3 years of experience in technical writing, preferably in cybersecurity or IT policy documentation.
  • Understanding of the NIST Cybersecurity Framework (CSF) version 2.0 and experience in writing policies based on CSF for government agencies.
  • Knowledge of NIST 800-53 and other Federal level Information Security Policies and Requirements (e.g., FISMA, FedRAMP, OMB, RMF, FIPS, FTI Requirements, FAR, etc.), laws, regulations, policies, and ethics as they relate to cybersecurity and privacy
  • Expert in Microsoft suite of word processing, spreadsheet, imaging, and telecommunications software.
  • Proficiency in drafting technical reports, plans, and related correspondence.
  • Ability to effectively communicate technical cybersecurity concepts to non-technical stakeholders, including leaders of federal agencies.
  • Strong analytical and problem-solving skills.
  • Skills in administrative planning activities, including preparation of functional and specific support plans, preparing and managing correspondence, and staffing procedures
  • Skills in preparing drafts, technical reports, plans, and related correspondence
  • Excellent written and verbal communication skills.
  • Ability to work effectively both independently and as part of a team.

Preferred:

  • Relevant certifications (e.g., Security+ or CISSP)
  • Experience developing in Confluence

Clearance Requirements:

  • Must be able to obtain and maintain Public Trust

The Company

We believe in generating success collaboratively, enabling long-term mission success, and building trust for the next challenge. With you as our partner, let’s solve challenges, think innovatively, and maximize impact. As a valued member of our team, you have the unique opportunity to work in a diverse range of technology and business career paths, all while supporting our nation and delivering innovative technology solutions. We are a close community of experts who pride ourselves on creating an environment defined by teamwork, dedication, and excellence.

We hold three ISO certifications (27001:2013, 20000-1:2011, 9001:2015) and two CMMI ML 3 ratings (DEV and SVC).

Industry Recognition

Growth | Inc 5000’s Fastest Growing Private Companies, DC Metro List Fastest Growing; Washington Business Journal: Fastest Growing Companies, Top Performing Small Technology Companies in Greater D.C.

Culture | Northern Virginia Technology Council Tech 100 Honoree; Virginia Best Place to Work; Washington Business Journal: Best Places to Work, Corporate Diversity Index Winner – Mid-Size Companies, Companies Owned by People of Color; Department of Labor’s HireVets for our work helping veterans transition; SECAF Award of Excellence finalist; Victory Military Friendly Brand; Virginia Values Veterans (V3); Cystic Fibrosis Foundation Corporate Breath Award

Benefits

We offer a competitive benefits package that includes paid time off, healthcare benefits, supplemental benefits, 401k including an employer match, discount perks, rewards, and more. 

We invest in our employees – Every employee is eligible for education reimbursement for certifications, degrees, or professional development.  Reimbursement amounts may fluctuate due to IRS limitations. We want you to grow as an expert and a leader and offer flexibility for you to take a course, complete a certification, or engage in other professional growth and networking. We are committed to supporting your curiosity and sustaining a culture that prioritizes a commitment to continuous professional development. 

We work hard, we play hard. ITC is committed to incorporating fun into every day. We dedicate funds for activities – virtual and in-person – e.g., we host happy hours, holiday events, fitness & wellness events, and annual celebrations. In alignment with our commitment to our communities, we also host and attend charity galas/events. We appreciate your commitment to building a positive workspace for you to be creative, innovative, and happy.

AAEO & VEVRAA

ITC is an Affirmative Action/Equal Opportunity employer and a VEVRAA (Vietnam Era Veterans' Readjustment Assistance Act) Federal Contractor. As such, any personnel decisions (hire, promotion, job status, etc.) on applicants and employees are based on merit, qualifications, competence, and business needs, not on race, color, citizenship status, national origin, ancestry, sexual orientation, gender identity, age, religion, creed, physical or mental disability, pregnancy, childbirth or related medical condition, genetic information of the employee or family member of the employee, marital status, veteran status, political affiliation, or any other factor protected by federal, state or local law.

ITC is strongly committed to compliance with VEVRAA and other applicable federal, state, and local laws governing equal employment opportunity. We have developed comprehensive policies and procedures to ensure our hiring practices align with these requirements.

As part of our VEVRAA compliance efforts, ITC has established an affirmative action plan outlining our commitment to recruiting, hiring, and advancing protected veterans. This plan is regularly reviewed and updated to ensure its effectiveness.

We encourage protected veterans to self-identify during the application process. This information is strictly confidential and will only be used for reporting and compliance purposes as required by law. Providing this information is voluntary and will not impact your employment eligibility.

Our commitment to equal employment opportunity extends beyond legal compliance. We are dedicated to fostering an inclusive workplace where all employees, including protected veterans, are treated with dignity, respect, and fairness.

How to Apply

To apply to IT Concept Positions- Please click on the: “Apply for this Job” button at the bottom of this Job Description or the button at the top: “Application.”  Please upload your resume and complete all the application steps. You must submit the application for IT Concepts to be considered for a position.  If you need alternative application methods, please email careers@useitc.com and request assistance.  

Accommodations

To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. Reasonable Accommodations may be made to enable qualified individuals with disabilities to perform the essential functions. If you need to discuss reasonable accommodations, please email careers@useitc.com.  

#itccareers #LI-JG1

Average salary estimate

$156000 / YEARLY (est.)
min
max
$135200K
$176800K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Cybersecurity Policy Analyst (SSA), IT Concepts

Are you ready to make a real impact in the world of cybersecurity? IT Concepts, INC. (ITC) is looking for a passionate and driven Cybersecurity Policy Analyst to join our talented team. Located in a hybrid environment, you'll be at the forefront of supporting the Social Security Administration’s Office of Information Security. In this role, you will dive deep into the NIST Cybersecurity Framework (CSF) version 2.0, leveraging your knowledge and experience to help develop, maintain, and automate policy products that ensure robust security frameworks. As you collaborate with the OIS Policy Team, your research and analytical skills will shine as you interpret and integrate updated policies in compliance with NIST, OMB, and FISMA regulations. You’ll conduct reviews of vital documents to confirm their accuracy and validity while actively participating in discussions that drive policy changes and efficiencies. With your expertise in technical writing and understanding of cybersecurity, you’ll create clear, actionable reports and facilitate communication to promote policy awareness among stakeholders. At IT Concepts, we thrive on innovation, teamwork, and a commitment to professional development. If you’re eager to contribute to meaningful change within government security practices, we can’t wait to welcome you to our team. Join us in crafting policies that strengthen security and support our nation's vital interests.

Frequently Asked Questions (FAQs) for Cybersecurity Policy Analyst (SSA) Role at IT Concepts
What are the responsibilities of a Cybersecurity Policy Analyst at IT Concepts?

As a Cybersecurity Policy Analyst at IT Concepts, you will be integral to the Social Security Administration’s Office of Information Security (OIS). Your responsibilities include developing and maintaining policy products, analyzing updated language against federal mandates, conducting document reviews for accuracy, and facilitating policy discussions. You’ll also enhance workflows for policy processes, assist with audits, and prepare documentation for publication, ensuring the security framework adapts to evolving challenges.

Join Rise to see the full answer
What qualifications are required for the Cybersecurity Policy Analyst position at IT Concepts?

To qualify for the Cybersecurity Policy Analyst role at IT Concepts, you should hold a Bachelor's degree in computer science, information technology, or a related field. It is essential to have 1-3 years of relevant experience in technical writing, particularly in cybersecurity policies. Familiarity with the NIST Cybersecurity Framework version 2.0, NIST 800-53, and other federal security policies is necessary, as well as proficiency in Microsoft Office and strong analytical skills.

Join Rise to see the full answer
How does IT Concepts support employee professional development for Cybersecurity Policy Analysts?

IT Concepts is dedicated to the continuous professional growth of its employees. As a Cybersecurity Policy Analyst, you will have access to education reimbursement for certifications and degrees, allowing you to enhance your skills and qualifications. The company also encourages participation in networking and professional development activities, ensuring you are well-prepared for higher responsibilities and challenges in your career.

Join Rise to see the full answer
What is the work culture like for a Cybersecurity Policy Analyst at IT Concepts?

The work culture at IT Concepts is collaborative and innovative, centered on a commitment to delivering excellence while supporting national interests. As a Cybersecurity Policy Analyst, you will engage with a diverse team of experts who prioritize teamwork, continuous learning, and community engagement. IT Concepts fosters a positive work environment with various fun activities and wellness events, ensuring a balanced and enjoyable workplace.

Join Rise to see the full answer
What is the salary range for a Cybersecurity Policy Analyst at IT Concepts?

At IT Concepts, the hourly pay range for the Cybersecurity Policy Analyst position is between $65 and $85. Factors affecting compensation include geographic location, individual skills, education, and relevant experience. The company offers a competitive benefits package, ensuring that employees are rewarded for their expertise and contributions.

Join Rise to see the full answer
Common Interview Questions for Cybersecurity Policy Analyst (SSA)
Can you describe your experience with the NIST Cybersecurity Framework?

When answering this question, you should highlight your familiarity with NIST CSF version 2.0. Discuss how you have applied it in past roles, particularly in policy development or compliance. Illustrate with specific examples showing how you've collaborated with teams to integrate the framework into organizational policies effectively.

Join Rise to see the full answer
What techniques do you use for effective technical writing in cybersecurity?

To respond effectively, emphasize your writing process, including understanding your audience and maintaining clarity and accuracy. Mention techniques like using simple language, structuring content logically, and incorporating visuals when necessary to enhance comprehension, especially for non-technical stakeholders.

Join Rise to see the full answer
How do you ensure that your policy recommendations align with federal mandates?

Highlight your research skills and familiarity with the relevant federal mandates like NIST, OMB, and FISMA. Explain your systematic approach to reviewing documents, cross-referencing them against current regulations, and consulting with peers or legal teams to ensure your policy recommendations are compliant and effective.

Join Rise to see the full answer
What experience do you have in conducting audits or reviews of policy documents?

Discuss any previous roles where you actively participated in auditing policy documents. Be sure to explain your process for ensuring accuracy, the types of documentation you reviewed, and any metrics you used to evaluate the effectiveness of the policies, demonstrating your analytical prowess.

Join Rise to see the full answer
Describe a time when you had to communicate complex cybersecurity concepts to non-technical stakeholders.

Share a specific example where you successfully communicated intricate cybersecurity information to a non-technical audience. Focus on the methods you employed, such as using analogies or visuals and ensuring feedback to gauge understanding, illustrating your ability to bridge communication gaps effectively.

Join Rise to see the full answer
How do you prioritize tasks when managing multiple policy projects?

To answer this question, describe your time management strategies. Highlight tools you may use for tracking deadlines and priorities, such as project management software. Provide an example where you had to balance competing deadlines and how you ensured the prompt delivery of high-quality work.

Join Rise to see the full answer
What steps do you take when identifying gaps in established policies?

Elucidate your systematic approach to identifying policy gaps. Discuss your process of analyzing existing documentation, consulting with stakeholders, and referring to updated regulations. Include an instance when you successfully proposed enhancements that strengthened the policy framework.

Join Rise to see the full answer
Can you give an example of a project you automated in your previous experience?

Here, you should illustrate a successful project you automated, outlining the challenges faced initially, the steps you took to develop automation, and the overall impact on efficiency. Provide details on the tools or software you utilized and the outcomes achieved after implementing the automation.

Join Rise to see the full answer
What is your experience with the NIST Risk Management Framework?

In your response, discuss your knowledge and experience with the NIST Risk Management Framework, addressing how you've applied its principles in risk assessment or policy formulation in your previous roles. Provide specific examples of tasks performed using the RMF guidelines.

Join Rise to see the full answer
Why do you want to work as a Cybersecurity Policy Analyst at IT Concepts?

Here, relay your passion for cybersecurity and the values of IT Concepts that resonate with you, such as the emphasis on teamwork, innovation, and community impact. Share your excitement regarding the chance to contribute to meaningful projects and help strengthen national security policies.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
IT Concepts Remote No location specified
Posted 12 days ago
Photo of the Rise User
PingWind Hybrid National Capital Region, VA
Posted 3 days ago
Photo of the Rise User
Master Works Remote No location specified
Posted 4 days ago
Photo of the Rise User
PACCOR Remote 11 Listopada, 40-387 Katowice, Poland
Posted 6 days ago
Photo of the Rise User
Posted 2 days ago
Posted 4 days ago
Photo of the Rise User
Civica UK Ltd Remote No location specified
Posted 13 days ago

IT Concepts is providing development and integration services to Independent Software Vendors (ISVs) and end user companies worldwide. Our areas of expertise include Custom applications development using .Net platform, Web Designing and developmen...

79 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
December 25, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!